CVE-2026-105400
Received
Received - Intake
Resource Leak in ImageMagick via Malicious Magick Script
Vulnerability report for CVE-2026-105400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: VulnCheck
Description
Description
ImageMagick before 7.1.2-31 contains a resource leak vulnerability that allows attackers to leave file pointers open by supplying a crafted magick script. Attackers can process malicious magick scripts to leak file descriptors, potentially exhausting resources and causing denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ImageMagick | ImageMagick | 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-775 | The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed. |